Marc Dacier

dblp:76/5806 · DBLP profile ↗
← Back
31ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0003-3206-2030ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 23 · 4 first-author · 4 since 2021Computer networks · 5 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 A Reality Check on SBOM-based Vulnerability Management: An Empirical Study and A Path Forward
abstract
The Software Bill of Materials (SBOM) is a critical tool for securing the software supply chain (SSC), but its practical utility is undermined by inaccuracies in both its generation and its application in vulnerability scanning. This paper presents a large-scale empirical study on 2,414 open-source repositories to address these issues from a practical standpoint. First, we demonstrate that using lock files with strong package managers enables the generation of accurate and consistent SBOMs, establishing a reliable foundation for security analysis. Using this high-fidelity foundation, however, we expose a more fundamental flaw in practice: downstream vulnerability scanners produce a staggering 92.0% false positive rate in our case study. We pinpoint the primary cause as the flagging of vulnerabilities within unreachable code. We then demonstrate that function call analysis can effectively prune 61.9% of these false alarms. Our work validates a practical, two-stage approach for SSC security: first, generate an accurate SBOM using lock files and strong package managers, and second, enrich it with function call analysis to produce actionable, low-noise vulnerability reports that alleviate developers' alert fatigue.
Marc Dacier, Charalambos Konstantinou
CODASPY2
2025 A Closer Look At Modern Evasive Phishing Emails
abstract
The prevalence of sophisticated evasion techniques employed by phishing attacks in circumventing anti-phishing and email security measures is on the rise. The present study offers an exhaustive analysis of user-reported phishing messages pertaining to five companies over a ten-month period. These messages are of particular interest as they evaded all state of the art security layers in place and were identified by the recipients themselves.To study these elusive phishing attempts, we developed an analysis infrastructure, CrawlerBox, designed to overcome cloaking tactics that exploit browser fingerprinting and bot detection challenges. CrawlerBox is made available as an open-source tool to assist other researchers in pursuing further studies.Over the course of ten months, we gathered 1,551 user-reported messages that were confirmed to be malicious, with a particular focus on those targeting the harvesting of corporate credentials. Our analysis infrastructure enabled us to scan these messages and crawl any associated web resources, including URLs, embedded HTML, and JavaScript content.Our findings indicate that the majority of observed phishing attacks are low-volume but meticulously planned, exhibiting a high degree of premeditation and strategic preparation. In particular, a substantial number of sites were registered and had obtained TLS certificates several weeks before the attacks in order to avoid being flagged based on their young age, a common practice used by products to defeat phishing websites. Furthermore, it was observed that phishing pages are now safeguarded by advanced evasion mechanisms, such as bot detection services and open-source fingerprinting libraries. Notably, QR codes are increasingly used to embed phishing content. The victim needs to use a personal phone to flash the code and access the site; this activity will typically fall outside the perimeter of the corporate security defenses. These findings underscore the evolving sophistication of phishing threats and the urgent need for resilient systems to counter these advanced techniques, further emphasizing the critical role of robust infrastructures like CrawlerBox in enhancing the security and dependability of email systems.
Elyssa Boulila, Marc Dacier, Siva Prem Vengadessa Peroumal, Nicolas Veys, Simone Aonzo
DSN2
2025 The Developer, the RFC, and the Middlebox: An HTTP/2 Compliance Story
abstract
The current Internet landscape is shaped by intermediate elements, known as middleboxes, which disrupt the end-to-end principle the Internet was originally designed around. In [5], the authors examine the HTTP/1.1 ~protocol and demonstrate that assessing the compliance of a remote implementation with respect to its RFC ~is challenging, as middleboxes on the network path can alter application-layer content. This paper builds on their work by focusing on HTTP/2, a more efficient yet more complex protocol that is known to be vulnerable to denial-of-service attacks. We create a suite of 156 tests, more than three times the number conducted on HTTP/1.1, and analyze 12 popular proxies as well as 3 cloud proxies. This work not only investigates the current landscape of proxy implementations with respect to RFCs, but also examines the evolution of compliance over time in local proxies. We show that while there is an improvement compared to previous results in HTTP/1.1, none of the proxies are yet fully compliant.
Mahmoud Attia, Iliès Benhabbour, Marc Dacier
IMC3
2025 HTTP Conformance vs. Middleboxes: Identifying Where the Rules Actually Break Down
Iliès Benhabbour, Mahmoud Attia, Marc Dacier
PAM3
2023 Poster: The Impact of the Client Environment on Residential IP Proxies Detection
abstract
Residential IP Proxies (RESIPs) enable proxying out requests from a vast network of residential devices without inserting any information revealing it. While RESIPs can be used for legitimate purposes, previous studies also associate them with malicious activities. In our last work, we proposed a server-side detection method for RESIP connections based on the difference in the Round Trip Time at the TCP and TLS layers. In this new work, thanks to real-world connections, we investigate if and how specific factors in the client environment influence the technique. We show that genuine users utilizing web browsers or performing hotspots do not result in false positives for our technique. Moreover, our early results suggest that false positives caused by Mobile TCP Terminating Proxies used by mobile Internet Service Providers have a Round Trip Time difference higher than the detection threshold but much smaller than the average RESIP one. This suggests that we can reduce these false positives by highering the detection threshold for mobile connections.
Elisa Chiapponi, Marc Dacier, Olivier Thonnard
IMC2
2022 BADPASS: Bots Taking ADvantage of Proxy as a Service
Elisa Chiapponi, Marc Dacier, Olivier Thonnard, Mohamed Fangar, Vincent Rigal
ISPEC2
2016 Visualization of actionable knowledge to mitigate DRDoS attacks
abstract
Distributed Reflective Denial of Service attacks (DRDoS) represent an ever growing security threat. These attacks are characterized by spoofed UDP traffic that is sent to genuine machines, called amplifiers, whose response to the spoofed IP, i.e. the victim machine, is amplified and could be 500 times larger in size than the originating request. In this paper, we provide a method and a tool for Internet Service Providers (ISPs) to assess and visualize the amount of traffic that enters and leaves their network in case it contains innocent amplifiers. We show that amplified traffic usually goes undetected and can consume a significant bandwidth, even when a small number of amplifiers is present. The tool also enables ISPs to simulate various rule-based mitigation strategies and estimate their impact, based on real-world data obtained from amplification honeypots.
Michaël Aupetit 0001, Yury Zhauniarovich, Giorgos Vasiliadis, Marc Dacier, Yazan Boshmaf
VizSEC4
2016 Spammers operations: a multifaceted strategic analysis
abstract
Abstract There is a consensus in the anti‐spam community regarding the prevalence of spam botnets and the significant role they play in the worldwide spam problem. Nevertheless, far less attention has been devoted to studying thestrategic behaviorof spammers on a long‐term basis. This paper explores several facets of spammers operations by providing three essential perspectives: (i) we study the inter‐relationships among spam botnets through their aggregate spam campaigns, and we focus on identifying similarities or differences in theirmodus operandi; (ii) we look at the impact of theRustocktakedown on the botnet ecosystem; and (iii) we study the conjecture about spammers hijacking unused IP space to send spam in a stealthy way. To that end, we have analyzed over one million spam records collected bySymantec.cloud(formerly MessageLabs) through worldwide distributed spamtraps. Our methodology leverages techniques relying on data fusion and multi‐criteria decision analysis to extract intelligence from large spam data sets by automatically correlating spam campaigns according to various combinations of spam features. We also take advantage of node–link visualizations developed in the context of VIS‐SENSE, a research project aiming at developingVisual Analyticstechnologies for the security domain. Using these visualizations, we illustrate the tight relationships that exist among different botnet families (such asRustock/GrumorLethic/Maazben). Regarding the disruption ofRustockon 17 March 2011, our experimental results provide substantial evidence indicating that part of the botnet activity may have been offloaded toGrumshortly after the takedown operation. Finally, we analyzed over 1 year of spam data enriched with Border Gateway Protocol data and found that an increasing amount of spam may have been sent from IP blocks hijacked for several weeks or months, even though this phenomenon remains marginal at this time compared with spam sent from large botnets. Copyright © 2012 John Wiley & Sons, Ltd.
Olivier Thonnard, Pierre-Antoine Vervier, Marc Dacier
Secur. Commun. Networks3
2015 Mind Your Blocks: On the Stealthiness of Malicious BGP Hijacks
Pierre-Antoine Vervier, Olivier Thonnard, Marc Dacier
NDSS3
2015 Circuit Fingerprinting Attacks: Passive Deanonymization of Tor Hidden Services
Albert Kwon, Mashael Al Sabah, David Lazar, Marc Dacier, Srini Devadas
USENIX Security Symposium4
2014 Malicious BGP hijacks: Appearances can be deceiving
abstract
BGP hijacking is a well known threat to the Internet routing infrastructure. There has been considerable interest in developing tools that detect prefix hijacking but such systems usually identify a large number of events, many of them being due to some benign BGP engineering practice or misconfiguration. Ramachandran et al. [1] and later Hu et al. [2] also correlated suspicious routing events with spam and claimed to have found evidence of spammers temporarily stealing prefixes to send spam. In an effort to study at large scale the existence and the prevalence of malicious BGP hijacks in the Internet we developed a system which (i) identifies hijacks using BGP, traceroute and IRR data and (ii) investigates traffic originating from the reported networks with spam and netflow data. In this paper we present a real case where suspicious BGP announcements coincided with spam and web scam traffic from corresponding networks. Through this case study we show that a correlation of suspicious routing events with malicious activities is insufficient to evidence harmful BGP hijacks. We thus question previously reported cases and conclude that identifying malicious BGP hijacks requires additional data sources as well as feedback from network owners in order to reach decisive conclusions.
Pierre-Antoine Vervier, Quentin Jacquemart, Johann Schlamp, Olivier Thonnard, Georg Carle, Guillaume Urvoy-Keller, Ernst W. Biersack, Marc Dacier
ICC8
2011 Honeypot trace forensics: The observation viewpoint matters
Van-Hau Pham, Marc Dacier
Future Gener. Comput. Syst.2
2010 An Analysis of Rogue AV Campaigns
Marco Cova, Corrado Leita, Olivier Thonnard, Angelos D. Keromytis, Marc Dacier
RAID5
2009 Honeypot Traces Forensics: The Observation Viewpoint Matters
abstract
In this paper, we propose a method to identify and group together traces left on low interaction honeypots by machines belonging to the same botnet(s) without having any a priori information at our disposal regarding these botnets. In other terms, we offer a solution to detect new botnets thanks to very cheap and easily deployable solutions. The approach is validated thanks to several months of data collected with the worldwide distributed Leurre.com system. To distinguish the relevant traces from the other ones, we group them according to either the platforms, i.e. targets hit or the countries of origin of the attackers. We show that the choice of one of these two observation viewpoints dramatically influences the results obtained. Each one reveals unique botnets. We explain why. Last but not least, we show that these botnets remain active during very long periods of times, up to 700 days, even if the traces they left are only visible from time to time.
Van-Hau Pham, Marc Dacier
NSS2
2008 The Quest for Multi-headed Worms
Van-Hau Pham, Marc Dacier, Guillaume Urvoy-Keller, Taoufik En-Najjary
DIMVA2
2008 SGNET: Implementation insights
abstract
We present in this paper SGNET, a distributed framework to collect information on Internet attacks, with special attention to self-propagating malware and code injections. This framework is the result of our latest research work on the so-called ScriptGen technology. It is characterized by several unique characteristics that may allow it to provide in the future an extremely interesting perspective on the Internet attacks. In order to make it possible, we need to spread its observation points as much as possible to obtain a complete view on the different blocks of the IP space. We present here an overview of the characteristics of its design with special focus on the possibility to expand it and improve it with additional functional blocks. The SGNET is in fact an open initiative, integrating together tools produced by different research teams such as Argos (VU Amsterdam), Nepenthes, Anubis (TU Wien) and VirusTotal (Hispasec Sistemas). Everybody is welcome and encouraged to participate to this initiative, by hosting observation points and/or by extending this framework with additional modules.
Corrado Leita, Marc Dacier
NOMS2
2008 Automating the Analysis of Honeypot Data (Extended Abstract)
Olivier Thonnard, Jouni Viinikka, Corrado Leita, Marc Dacier
RAID4
2006 Automatic Handling of Protocol Dependencies and Reaction to 0-Day Attacks with ScriptGen Based Honeypots
Corrado Leita, Marc Dacier, Frédéric Massicotte
RAID2
2005 ScriptGen: an automated script generation tool for honeyd
abstract
Honeyd (N. Provos, 2004) is a popular tool developed by Niels Provos that offers a simple way to emulate services offered by several machines on a single PC. It is a so called low interaction honeypot. Responses to incoming requests are generated thanks to ad hoc scripts that need to be written by hand. As a result, few scripts exist, especially for services handling proprietary protocols. In this paper, we propose a method to alleviate these problems by automatically generating new scripts. We explain the method and describe its limitations. We analyze the quality of the generated scripts thanks to two different methods. On the one hand, we have launched known attacks against a machine running our scripts; on the other hand, we have deployed that machine on the Internet, next to a high interaction honeypot during two months. For those attackers that have targeted both machines, we can verify if our scripts have, or not, been able to fool them. We also discuss the various tuning parameters of the algorithm that can be set to either increase the quality of the script or, at the contrary, to reduce its complexity.
Corrado Leita, Ken Mermoud, Marc Dacier
ACSAC3
2004 Honeypots: Practical Means to Validate Malicious Fault Assumptions
abstract
We report on an experiment run with several honeypots for 4 months. The motivation of this work resides in our wish to use data collected by honeypots to validate fault assumptions required when designing intrusion-tolerant systems. This work in progress establishes the foundations for a feasibility study into that direction. After a review of the state of the art with respect to honeypots, we present our test bed, discuss results obtained and lessons learned. Avenues for future work are also proposed.
Marc Dacier, Fabien Pouget, Hervé Debar
PRDC1
2002 Mining intrusion detection alarms for actionable knowledge
abstract
In response to attacks against enterprise networks, administrators increasingly deploy intrusion detection systems. These systems monitor hosts, networks, and other resources for signs of security violations. The use of intrusion detection has given rise to another difficult problem, namely the handling of a generally large number of alarms. In this paper, we mine historical alarms to learn how future alarms can be handled more efficiently. First, we investigate episode rules with respect to their suitability in this approach. We report the difficulties encountered and the unexpected insights gained. In addition, we introduce a new conceptual clustering technique, and use it in extensive experiments with real-world data to show that intrusion detection alarms can be handled efficiently by using previously mined knowledge.
Klaus Julisch, Marc Dacier
KDD2
2000 A Lightweight Tool for Detecting Web Server Attacks
Magnus Almgren, Hervé Debar, Marc Dacier
NDSS3
2000 Intrusion Detection Using Variable-Length Audit Trail Patterns
Andreas Wespi, Marc Dacier, Hervé Debar
Recent Advances in Intrusion Detection2
2000 Fixed- vs. Variable-Length Patterns for Detecting Suspicious Process Behavior
abstract
This paper addresses the problem of creating patterns that can be used to model the normal behavior of a given process. The models can be used for intrusion-detection purposes. First, we present a novel method to generate input data sets that enable us to observe the normal behavior of a process in a secure environment. Second, we propose various techniques to derive either fixed-length or variable-length patterns from the input data sets. We show the advantages and drawbacks of each technique, based on the results of the experiments we have run on our testbed.
Andreas Wespi, Hervé Debar, Marc Dacier, Mehdi Nassehi
J. Comput. Secur.3
1999 Intrusion Detection Mechanism to Detect Reachability Attacks in PNNI Networks
Yves Cosendai, Marc Dacier, Paolo Scotton
Recent Advances in Intrusion Detection2
1999 Intrusion detection
Marc Dacier, Kathleen Jackson
Comput. Networks1
1999 Towards a taxonomy of intrusion-detection systems
Hervé Debar, Marc Dacier, Andreas Wespi
Comput. Networks2
1998 Fixed vs. Variable-Length Patterns for Detecting Suspicious Process Behavior
Hervé Debar, Marc Dacier, Mehdi Nassehi, Andreas Wespi
ESORICS2
1996 Models and tools for quantitative assessment of operational security
Marc Dacier, Yves Deswarte, Mohamed Kaâniche
SEC1
1994 Privilege Graph: an Extension to the Typed Access Matrix Model
Marc Dacier, Yves Deswarte
ESORICS1
1993 A Petri Net Representation of the Take-Grant Model
abstract
The Take-Grant model is formalised with a Petri net notation. It is shown that this approach offers a convenient way to deal with the problem of determining the cooperation required to share or steal rights. An algorithm is proposed that finds all rights that a subject can steal with the help of a given set of conspirators. With the Petri net abstraction, the problem can be solved in linear time. It is compared to another algorithm exposed in the literature that requires n/sup 2/ operations for a n subject graph.>
Marc Dacier
CSFW1